Coordinated vulnerability disclosures and public security notes related to my research on software and networked systems security.
ASN1SCC is ESA's open-source ASN.1 compiler used to generate code for embedded and space-oriented systems. This disclosure concerns vulnerabilities found while studying parser and compiler security in software supply chains for critical networked systems.
The CVE identifiers below are tracked through ESA’s GitHub Security Advisories for ASN1SCC, where the advisories have already been published by the maintainer. Technical details on this site are aligned with that public advisory material.
ESA ASN1SCC Security Advisories
For a plain-language explanation of the issue and its supply-chain relevance, see ASN.1 Strikes Back.
This page explains the security advisories already published by the maintainer on GitHub. No exploit code is published here: the aim is to keep an inspectable record of the research, not to provide ready-to-use attack material.